GitLab CE/EE Device OAuth Flow Bypass Vulnerability

Vulnerability

A vulnerability exists in GitLab CE/EE versions 17.3 prior to 17.9.8, 17.10 prior to 17.10.6, and 17.11 prior to 17.11.2. This vulnerability allows attackers to bypass protections in the Device OAuth flow, enabling the submission of authorization forms with minimal user interaction.

Impact

Exploitation of this vulnerability could lead to unauthorized OAuth authorization, allowing attackers to gain access to user data or perform actions on behalf of the user.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.